Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Pending] error at start up and suspect infection

[Fixed] Hijackthis! Logs - [Pending] error at start up and suspect infection posted in the Security & Safety forums; hi, i get the following error messages at start up and suspect our "friends" virus in my machine: (a) hkcmd module has encountered a problem and needs to close (b) ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-17-2007
predator's Avatar
Gold Member
My PC
 
Join Date: Aug 2005
Location: Gaborone
Posts: 212
PC Experience: Always Learning
predator - See this Members User comments on their Profile page
Send a message via Yahoo to predator
Default [Pending] error at start up and suspect infection

hi,

i get the following error messages at start up and suspect our "friends" virus in my machine:

(a) hkcmd module has encountered a problem and needs to close
(b) windows can't find "c:\windows\sembako-d.fzjljg.exe."

I have attached a copy of hijackthis log and would appreciate if you could get it checked for me.

TTFN

Pred
Attached Files
File Type: txt hijackthislog.txt (7.8 KB, 4 views)


  #2  
Old 01-17-2007
GaRHaR's Avatar
Elite Member
My PC
 
Join Date: Jul 2006
Location: Western Australia
Posts: 6,042
PC Experience: Elite PC Guru
GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page GaRHaR - See this Members User comments on their Profile page
Send a message via ICQ to GaRHaR Send a message via MSN to GaRHaR Send a message via Yahoo to GaRHaR
Default

Hi predator - hkcmd is nothing more then a windows process - but can safely be stopped from running on startup.
the sembako-d.fzjljg.exe is a bit more worrying.

One of the security team will be along shortly to check out your log for you.


__________________


"Study without desire spoils the memory, and it retains nothing that it takes in."
- Leonardo da Vinci

"I believe in Christianity as I believe that the sun has risen: not only because I see it, but because by it I see everything else."
- C. S. Lewis
  #3  
Old 01-17-2007
predator's Avatar
Gold Member
My PC
 
Join Date: Aug 2005
Location: Gaborone
Posts: 212
PC Experience: Always Learning
predator - See this Members User comments on their Profile page
Send a message via Yahoo to predator
Default

Ok, will hang around


  #4  
Old 01-18-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Run HijackThis and check the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = mommy kiss me mascara my at mommykiss.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/5/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/5/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/5/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/5/search.php?qq=%s
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\sembako-dfzjljg.exe"
O1 - Hosts: 209.66.114.130 sitefinder.verisign.com
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Close all other windows except HijackThis and press "Fix Checked". Then close HijackThis and restart the computer.

Download ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Next download, install, and update AVG Anti-Spyware 7.5
  1. Save the installer to desktop
  2. Double click the installer, select your language, and then select OK
  3. Click NEXT>>Do or don't read the "User License Agreement"
    Select I Agree>>>NEXT>>>INSTALL
  4. AVG will now install and afterwards click FINISH
  5. AVG Anti-Spyware 7.5 should now Load
  6. Click the Update tab at the top. Under Manual Update click Start update.
  7. After the update finishes (the status bar at the bottom will display "Update successful")
  8. Close AVG Anti-Spyware 7.5. Do not run it yet.
Reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode at the top, on the screen that appears.
Sign in with your normal user account

Once in safe mode
  • Then run AVG Anti-Spyware 7.5 and click on the Scanner tab at the top
  • Click the "Settings" tab and then change the recommended action to Quarantine and ensure that Automatically generate report after every scan is selected and
    Uncheck "Only if Threats are found"
  • Click back to the "Scan" tab and then click on Complete System Scan.
    This scan can take quite a while to run, so be prepared.
  • AVG Anti-Spyware 7.5 will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG Anti-Spyware 7.5 will display "All actions have been applied" on the right hand side.
  • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
Post this file, along with a new HijackThis log.


  #5  
Old 01-18-2007
predator's Avatar
Gold Member
My PC
 
Join Date: Aug 2005
Location: Gaborone
Posts: 212
PC Experience: Always Learning
predator - See this Members User comments on their Profile page
Send a message via Yahoo to predator
Default

Herewith scan report as requested
Attached Files
File Type: txt hijackthislog.txt (6.5 KB, 7 views)
File Type: txt Report-Scan-20070118-143457.txt (9.2 KB, 4 views)


  #6  
Old 01-19-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Download ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


Then run Panda ActiveScan.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report.


  #7  
Old 01-20-2007
predator's Avatar
Gold Member
My PC
 
Join Date: Aug 2005
Location: Gaborone
Posts: 212
PC Experience: Always Learning
predator - See this Members User comments on their Profile page
Send a message via Yahoo to predator
Default

Herewith scan report, thanks in advance.

Pred.
Attached Files
File Type: txt Activescan.txt (3.2 KB, 3 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:50 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top